Closed Bug 1921221 (https-first-release) Opened 1 year ago Closed 1 year ago

[meta] HTTPS-First by default in Release

Categories

(Core :: DOM: Security, task)

task

Tracking

()

RESOLVED FIXED
136 Branch
Tracking Status
relnote-firefox --- 136+
firefox136 --- fixed

People

(Reporter: freddy, Assigned: freddy)

References

(Blocks 1 open bug)

Details

(Keywords: meta, webcompat:platform-bug, Whiteboard: [domsecurity-meta])

Attachments

(1 file)

This is the meta bug for shipping HTTPS-First to release for all of our users.

There is a long tail of HTTPS-First bugs blocking bug 1704453, which we should ideally fix but not all of them will make it to our scope for making the feature release-ready

Depends on: 1919544
Severity: -- → N/A
Whiteboard: [domsecurity-meta]
Depends on: 1904238
Alias: https-first-release
Assignee: nobody → fbraun
Status: NEW → ASSIGNED
No longer depends on: 1921227
No longer depends on: 1746173
No longer depends on: 1725390
No longer depends on: 1915107
Depends on: 1901120
Depends on: 1942810

Nominating bug 1943551 for consideration. I believe we should figure out the test automation story before we annoy web developers who are testing with Firefox.

Depends on: 1943551
Status: ASSIGNED → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Target Milestone: --- → 136 Branch

:freddy could you consider nominating this for a release note? (Process info)

This is the note we used when this was enabled in nightly:

Starting with Firefox 129, Firefox Nightly will automatically try to use a secure HTTPS connection whenever possible when loading a page. This behavior is known as "HTTPS-First", or "HTTPS Upgrades", and has been the default in Firefox's private browsing mode since Firefox 91. Here is a blog post from when this feature was introduced in Private Browsing.

Flags: needinfo?(fbraun)

Release Note Request (optional, but appreciated)
[Why is this notable]: We will change page loads through links that start with HTTP to try and use HTTPS instead. If HTTPS does not work, we fall back to HTTP gracefully.
[Affects Firefox for Android]: Yes
[Suggested wording]: Firefox will upgrade page loads to HTTPS and gracefully fall back to HTTP if that does not succeed.
[Links (documentation, blog post, etc)]: https://support.mozilla.org/en-US/kb/https-first

relnote-firefox: --- → ?
Flags: needinfo?(fbraun)

Thanks, added to the Fx136 nightly release notes, please allow 30 minutes for the site to update.
Keeping the relnote-firefox flag as ? to keep it on the radar for inclusion in the final Fx136 release notes.

No longer depends on: 1877935
No longer depends on: 1949091
Depends on: 1949091
No longer depends on: 1949091

Moved the webcompat:platform-bug from bug 1704453 to here, to properly reflect that the main feature has long since landed.

You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: